WordPress Plugin Vulnerabilities

Slider Pro <= 1.0.0 - Unauthenticated Sensitive Data Disclosure via sliderpro_multiple_images

Description

The plugin does not perform any capability or authorisation check on one of its AJAX actions, allowing unauthenticated users to retrieve the title, excerpt and permalink of non-public posts, including drafts, pending, scheduled, private and trashed posts, as well as post revisions and media metadata.

Proof of Concept

Affects Plugins

No known fix

References

Classification

Type
SENSITIVE DATA DISCLOSURE
CWE

Miscellaneous

Original Researcher
Seongwon Lee
Submitter
Seongwon Lee
Verified
Yes

Timeline

Publicly Published
2026-10-03 (about 2 days ago)
Added
2026-09-26 (about 9 days ago)
Last Updated
2026-09-26 (about 9 days ago)

Other